MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ebbee002097fb71812a1a1e847f80fc7de3b2819dff4c0c30235606965b6270. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0ebbee002097fb71812a1a1e847f80fc7de3b2819dff4c0c30235606965b6270
SHA3-384 hash: 9f0344e0bbe88a64bea0e0ca52ea9a5af99e4aaeff93d13b37e17b8c77894eb23ebc572c8f0619bf846369b69aa379b2
SHA1 hash: c2f67664badf48314ab3f53f4b2ffa5c22155b9f
MD5 hash: f5603ea5641f7798be320f37aecfb1e7
humanhash: iowa-cola-mobile-nineteen
File name:dlr.mips
Download: download sample
Signature Mirai
File size:3'052 bytes
First seen:2025-12-06 07:28:37 UTC
Last seen:2025-12-06 09:24:09 UTC
File type: elf
MIME type:application/x-executable
ssdeep 48:BudpwV2iITi2QkjNikLpt6wqJkCE8EUPSHkInzHhmVAuPHx79dL+mZfKqubpE68y:odpwVtmi2QvklGTE8ESSEIz4lphdALXj
TLSH T1E8510F9F1A12DFE4F0A8D53847B35E65435A13DB22E59686F1ACC6000E6234D9C5F6F4
telfhash t18ca0023cc4700370400cdc20801c5d1cd42000ef06162c03dd4814388a713015c00e4c
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
74
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-12-06T06:30:00Z UTC
Last seen:
2025-12-07T18:25:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1827868 Sample: dlr.mips.elf Startdate: 06/12/2025 Architecture: LINUX Score: 48 22 Multi AV Scanner detection for submitted file 2->22 7 dlr.mips.elf Hari 2->7         started        process3 file4 20 /tmp/Hari, ELF 7->20 dropped 10 Hari 7->10         started        process5 process6 12 Hari 10->12         started        14 Hari 10->14         started        16 Hari 10->16         started        18 1018 other processes 10->18
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-06 07:16:03 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 37 (37.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 0ebbee002097fb71812a1a1e847f80fc7de3b2819dff4c0c30235606965b6270

(this sample)

  
Delivery method
Distributed via web download

Comments